Rn4870 Firmware
Vendor:
First CVE: Dec 19, 2022 · Active for 3 years
8
Total CVEs
More Total CVEs than 87% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rn4870 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2022
3 years ago
Most Recent CVE
Feb 8, 2023
1,265 days ago
CVE Severity & Scoring
Rn4870 Firmware8 CVEs
75%
25%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (12.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (87.5%)
Attack Complexity
Low6 (75.0%)
High2 (25.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46403HIGH The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages. | Dec 19, 2022 | 8.6 | 27 | NO | NO |
CVE-2022-46402MEDIUM The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values. | Dec 19, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-45191MEDIUM An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm message with wrong values. | Feb 8, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-46401MEDIUM The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete. | Dec 19, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-46400MEDIUM The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing. | Dec 19, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-45190MEDIUM An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device. | Feb 8, 2023 | 5.3 | 19 | NO | NO |
CVE-2022-46399HIGH The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero. | Dec 19, 2022 | 7.5 | 19 | NO | NO |
CVE-2022-45192MEDIUM An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext encryption pause request. | Feb 8, 2023 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Rn4870 Firmware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.43 | 8 | 6.5 | 0.5% | 0 | 0 |